Information Processing System
The information processing system addresses the challenge of detecting and mitigating malware in HCI environments by monitoring encryption operations and suspending unauthorized data writes, effectively preventing ransomware-induced data overwrite and ensuring data integrity.
Patent Information
- Application Number
- JP2022004239
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-01-14
- Publication Date
- 2025-05-08
- Estimated Expiration
- 2042-01-14
AI Technical Summary
Existing data management systems, particularly in HCI environments, face challenges in detecting and mitigating malware threats, especially zero-day ransomware, which can lead to data encryption and overwrite, causing significant damage.
An information processing system is configured to monitor instruction information for encryption operations, detecting unauthorized key data usage. When unauthorized key data is set, the system issues a suspension request to halt data writing processes, preventing data overwrite by malicious actors like ransomware.
This solution enhances the reliability of data management systems by preventing unauthorized data overwrite, thereby protecting against ransomware attacks and ensuring data integrity.
Smart Images

Figure 0007672998000001 
Figure 0007672998000002 
Figure 0007672998000003
Abstract
Description
[Technical field]
[0001] The present invention generally relates to techniques for managing data. [Background technology]
[0002] Traditionally, ICT infrastructure systems have often been composed of three layers, known as the 3-tier model. The three layers are the server / compute layer, which provides resources for calculations, the storage layer, which provides resources for storing data, and the network layer, which provides resources connecting the compute layer resources and the storage layer resources. When the system is configured in this way, users have the advantage of being able to flexibly introduce the resources they need. On the other hand, there has been a recent demand for the rapid launch of services such as SNS and video distribution. Therefore, if it is intended to quickly launch these services with a small-scale hardware configuration, it is necessary to configure the system in a 3-tier model, and the hardware costs and the effort required for configuration are relatively large, which can be a factor in hindering the launch of services.
[0003] Against this background, systems known as hyper-converged infrastructure (HCI) have recently been commercialized. HCI-type systems configure compute, storage, and the network between them within a single appliance according to the application. In recent years, advances in virtualization technology have led to an increasing number of appliances being introduced with a virtual machine monitor (hypervisor) and multiple virtual machines (VMs) being built on the hypervisor, with each being used as a compute device or a storage device. By arranging such appliances in parallel and connecting them together, the system can be easily expanded.
[0004] As mentioned above, in an HCI system, the physical resources (processors, memory, network cards, etc.) installed in the appliance are shared by multiple VMs, hypervisors, etc. Therefore, if a Root of Compromise (RoC) occurs in any of the resources, there is a high possibility that all resources in the system will be compromised. One of the factors that can cause an RoC is malware that has infiltrated into the network to which the HCI system is connected.
[0005] Many recent malware, when it successfully infiltrates a device connected to a network, searches for other resources connected to that network that have not yet been removed vulnerability, infiltrates and infects the resources it finds, and then begins infringing activities in response to commands from a malware control server (such as a command and control server; C2 server) outside the network. One of the reasons for this is that by communicating with the C2 server, it is possible to confirm that the environment in which the malware infiltrated is not a decoy environment. The following inventions are examples of inventions that detect such malware.
[0006] In the invention described in Patent Document 1, when there is a client device connected to a network, malware invades the client device in the form of an email attachment or the like by monitoring files sent to the client device in the middle of the network (before the client device) and isolating files suspected to be malware, thereby preventing the client device from being infected with malware. Files that the monitoring unit determines to be highly likely to be malware are temporarily stored in a quarantine unit that communicates with the monitoring unit. Whether or not the file is malware is evaluated based on the latest information on malware, which is obtained from a reputation server in a remote location at any time. For files that are evaluated to be malware, information identifying the file (hash value, signature, etc.) is registered in an antivirus database. With the above-mentioned mechanism, whether or not a file is malware is determined based on the latest information, and information on malware managed by the system itself is updated.
[0007] In the invention described in Patent Document 2, when a file suspected to be malware is about to be saved in a client device through a process such as downloading, the file is put into a sandbox environment and run, and the behavior of the file is analyzed to evaluate whether the file is malware. The evaluation is achieved by analyzing whether the network communication by the file is similar to network communication by malware. [Prior art documents] [Patent documents]
[0008] [Patent Document 1] International Publication No. 2014 / 070499 [Patent Document 2] U.S. Pat. No. 10,389,740 Summary of the Invention [Problem to be solved by the invention]
[0009] Both the invention described in Patent Document 1 and the invention described in Patent Document 2 are applicable and useful if a VM in an HCI type system is considered as a client device in the invention.
[0010] However, in the invention described in Patent Document 1, the authenticity of malware is evaluated based on information acquired from an external malware-related information collection unit, such as a reputation server. Therefore, even if a certain file is malware, if the information acquired from the reputation server does not include information about the file, the file is not determined to be malware.
[0011] Furthermore, in the invention described in Patent Document 2, it takes a certain amount of time to analyze a file suspected of being malware. Therefore, if data infringement progresses before the analysis is completed, or if the file is temporarily quarantined until the authenticity of the malware is confirmed, there is a problem that even if the file is not malware, it cannot be used until the analysis is completed.
[0012] In particular, if the malware that has infiltrated a network is a zero-day ransomware program (ransomware), the invention described in Patent Document 1 will not be able to detect it, and in the invention described in Patent Document 2, there is a concern that the infringement will progress as data stored in storage devices is overwritten with data encrypted by the ransomware using an accelerator, resulting in greater damage.
[0013] The present invention has been made in consideration of the above points, and aims to propose an information processing system etc. that can appropriately manage data stored in a storage device. [Means for solving the problem]
[0014] In order to solve the problem, in the present invention, an information processing system includes an accelerator capable of encrypting data, a storage device, a compute unit that runs an application program, a storage control unit that processes a request issued by the compute unit to read and write data to a specific storage space in accordance with an instruction issued by the application program, and a monitoring unit that monitors command information issued from the compute unit that sets in the accelerator key data to be used by the compute unit specified by the application program in order for the application program to encrypt data using the accelerator, and when the monitoring unit detects that the key data set in the accelerator by the command information is not key data whose use is permitted, it issues an interruption request to the storage control unit to interrupt processing related to writing of data, and upon receiving an instruction from the application program, the compute unit reads data from the storage device, encrypts the read data using the accelerator, and issues an instruction to the storage control unit to write the encrypted data to the storage device, and when the storage control unit receives the interruption request, it interrupts processing related to writing of data to the storage device.
[0015] In the above configuration, for example, if it is detected that the key data to be set in the accelerator is unauthorized key data, the write process is not performed, thereby preventing the data in the storage device from being overwritten after the key data is set by ransomware. Effect of the Invention
[0016] According to the present invention, a highly reliable information processing system can be realized. Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments. [Brief description of the drawings]
[0017] [Figure 1]1 is a block diagram showing an example of the configuration of an HCI type information processing system according to a first embodiment. [Diagram 2] 1 is a block diagram showing an example of the configuration of an HCI type information processing system according to a first embodiment. [Diagram 3] 1 is a block diagram showing an example of the configuration of a 3-tier information processing system according to a first embodiment. [Figure 4] 1 is a block diagram showing an example of the configuration of a 3-tier information processing system according to a first embodiment. [Diagram 5] FIG. 2 is a diagram illustrating an example of the configuration of an HCI node (with a data storage drive), a drive box, a storage control node (with a data storage drive), and a key management server according to the first embodiment. [Figure 6] FIG. 2 is a diagram illustrating an example of the configuration of an HCI node (without a data storage drive) and a storage control node (without a data storage drive) according to the first embodiment. [Figure 7] FIG. 2 is a diagram illustrating an example of a configuration of a compute node according to the first embodiment. [Figure 8] FIG. 2 is a diagram illustrating an example of programs and data arranged in a memory of an HCI node according to the first embodiment. [Figure 9] 4] FIG. 4 illustrates an example of programs and data arranged in a memory of a storage control node according to the first embodiment. [Figure 10] FIG. 2 is a diagram illustrating an example of programs and data arranged in a memory of a compute node according to the first embodiment. [Figure 11] FIG. 11 is a diagram showing an example of available key related information arranged in the memory of an HCI node according to the first embodiment. [Figure 12] 11 is a diagram illustrating an example of available key related information stored in a memory of a storage control node according to the first embodiment. FIG. [Figure 13] FIG. 2 is a diagram illustrating an example of available key related information stored in a memory of a compute node according to the first embodiment. [Figure 14]FIG. 4 is a diagram showing an example of command information according to the first embodiment. [Figure 15] FIG. 2 is a diagram illustrating an example of a processing sequence according to the first embodiment. [Figure 16] FIG. 2 is a diagram illustrating an example of a processing sequence according to the first embodiment. [Figure 17] FIG. 2 is a diagram illustrating an example of a processing sequence according to the first embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0018] (I) First embodiment The present invention relates to an information processing system, a storage system, a data transfer method, and a data encryption / decryption method, and is suitable for application to, for example, a system equipped with a flash drive. An embodiment of the present invention will be described in detail below. However, the present invention is not limited to the embodiment.
[0019] In the information processing system of this embodiment, for example, a server device including a compute unit and a storage control unit is provided with a key monitoring unit that keeps track of all key data permitted for use. The key monitoring unit monitors key data used for encryption set in the encryption-related calculation accelerator. When the key monitoring unit detects that unknown key data has been set in the encryption-related calculation accelerator, it transmits a request not to perform I / O processing of data to the storage control unit. When the storage control unit receives the request from the key monitoring unit, it does not perform I / O processing on a storage space (e.g., a volume) managed by the storage control unit. The key data used for encryption may be key data for encryption / decryption, or may be key data for encryption.
[0020] According to the above configuration, for example, when a software program that is not permitted for installation, such as ransomware, encrypts data using a cryptography-related calculation accelerator, it is possible to prevent the original data from being overwritten with the encrypted data at an early stage.
[0021] In this embodiment, an HCI type system and a 3-Tier type system will be described as information processing systems. In addition, in this embodiment, a case where ransomware invades an HCI node of an HCI type system, a storage control node of a 3-Tier type system, and a compute node of a 3-Tier type system will be described as an example.
[0022] The present embodiment will be described in detail below with reference to the drawings. The following description and drawings are examples for explaining the present invention, and are omitted and simplified as appropriate for clarity of explanation. In addition, not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention. The present invention is not limited to the embodiments, and all application examples that match the idea of the present invention are included in the technical scope of the present invention. A person skilled in the art can make various additions, modifications, etc. within the scope of the present invention. The present invention can be implemented in various other forms. Unless otherwise specified, each component may be multiple or singular.
[0023] In the following explanation, various information may be explained using expressions such as tables, lists, and the like, but the various information may be expressed in other data structures. To indicate independence from the data structure, "XX table," "XX list," and the like may be referred to as "XX information." When explaining the content of each piece of information, expressions such as "identification information," "identifier," "name," "ID," and "number" are used, but these are interchangeable.
[0024] In the following description, when elements of the same kind are described without distinction, the reference signs or common numbers in the reference signs are used, or the reference signs are omitted. When elements of the same kind are described while being distinguished, the reference signs of the elements may be used, or an ID assigned to the elements may be used instead of the reference signs.
[0025] A program may be installed in a device such as a computer from a program source. The program source may be, for example, a program distribution server or a computer-readable storage medium. When the program source is a program distribution server, the program distribution server includes a processor (e.g., a Central Processing Unit; CPU) and a storage resource, and the storage resource may further store a distribution program and a program to be distributed. Then, the processor of the program distribution server may execute the distribution program, thereby distributing the program to be distributed to other computers. In the following description, two or more programs may be realized as one program, and one program may be realized as two or more programs.
[0026] The designations "first," "second," "third," and the like in this specification are given to identify components and do not necessarily limit the number or order. Furthermore, numbers for identifying components are used in each context, and a number used in one context does not necessarily indicate the same configuration in another context. Furthermore, a component identified by a certain number is not prevented from also having the function of a component identified by another number.
[0027] 1 is a block diagram showing an example of the configuration of an HCI type information processing system according to this embodiment. The information processing system is configured with one or more HCI nodes 100, 101, 102 and a key management server 130 as elements. The HCI nodes 100, 101, 102 are represented by adding suffix numbers 0, 1, and 2. The HCI nodes are connected by a management communication network 111 and a data communication network 110. Management information is transferred over the management communication network 111, and data is transferred over the data communication network 110.
[0028] FIG. 2 is a block diagram showing an example of the configuration of an HCI type information processing system according to this embodiment, similar to FIG. 1. However, in this information processing system, a storage drive (drive) for storing data is mounted in a drive box outside the HCI node, and the drive box is connected to each HCI node via a network. This information processing system is configured with one or more HCI nodes 200, 201, 202, a key management server similar to the key management server 130, and drive boxes 210, 211 as elements. The HCI nodes 200, 201, 202 are represented by adding suffix numbers 0 to 2, and the drive boxes 210, 211 are represented by adding suffix numbers 0 to 1. The HCI nodes 200, 201, 202 and the drive boxes 210, 211 are connected by a management communication network 111 and a data communication network 110. Management information is transferred on the management communication network 111, and data is transferred on the data communication network 110.
[0029] 3 is a block diagram showing an example of the configuration of a 3-tier information processing system according to this embodiment. The information processing system is configured with one or more compute nodes 340 and 341, a key management server similar to the key management server 130, and storage control nodes 300, 301, and 302 as elements. The compute nodes 340 and 341 are represented by adding suffix numbers 0 to 1, and the storage control nodes 300, 301, and 302 are represented by adding suffix numbers 0 to 2. The compute nodes 340 and 341 and the storage control nodes 300, 301, and 302 are connected to a management communication network 111. The compute nodes 340 and 341 and the storage control nodes 300, 301, and 302 are connected to a storage communication network 311, and the storage control nodes 300, 301, and 302 are connected to a back-end communication network 310. Management information is transferred on the management communication network 111. Data is transferred between the compute nodes and the storage control nodes over the storage communication network 311, and between the storage control nodes over the back-end communication network 310.
[0030] 4 is a block diagram showing an example of the configuration of a 3-tier information processing system according to this embodiment. The information processing system is configured with one or more compute nodes 340, 341, a key management server similar to the key management server 130, storage control nodes 400, 401, 402, and drive boxes 210, 211 as elements. The compute nodes 340, 341 are represented by adding suffix numbers 0 to 1. The storage control nodes 400, 401, 402 are represented by adding suffix numbers 0 to 2. The drive boxes 210, 211 are represented by adding suffix numbers 0 to 1. The compute nodes 340, 341, the storage control nodes 400, 401, 402, and the drive boxes 210, 211 are connected to a management communication network 111. Furthermore, the compute nodes 340 and 341 and the storage control nodes 400, 401 and 402 are connected to a storage communication network 311, and the storage control nodes 400, 401 and 402 and the drive boxes 210 and 211 are connected to a back-end communication network 310. Management information is transferred over the management communication network 111. Data is transferred between the compute nodes and the storage control nodes over the storage communication network 311, and between the storage control nodes and the drive boxes over the back-end communication network 310.
[0031] Next, we will briefly explain the roles of the HCI node, drive box, storage control node, and compute node shown in Figures 1 to 4.
[0032] HCI nodes 100, 101, and 102 are general-purpose computer devices that run application software programs (application programs) on their respective HCI nodes and have built-in drives for storing data used by the application programs. HCI nodes 200, 201, and 202 are the same as HCI nodes 100, 101, and 102, except that they do not have built-in drives. In the following, unless otherwise specified, "data" refers to data used by the application programs.
[0033] The drive boxes 210 and 211 are appliances that typically have multiple drives connected internally for storing data, and receive data write requests from HCI nodes 200, 201, 202 and storage control nodes 400, 401, 402 that do not have built-in drives for storing data, write the received data to the drive, or receive data read requests from the drive and send the data to the requester.
[0034] The storage control nodes 300, 301, 302 and the storage control nodes 400, 401, 402 are general-purpose computer devices that receive data write requests and read requests from the compute nodes 340, 341, and write the requested data to a drive or drive box mounted therein or read the requested data from the drive or drive box depending on the configuration. In this embodiment, the storage control nodes 300, 301, 302 are in a form in which a drive for saving data is built in, while the storage control nodes 400, 401, 402 are in a form in which a drive is not built in and data is saved in the drive boxes 210, 211.
[0035] The compute nodes 340 and 341 are general-purpose computer devices that function as hosts for the storage control nodes 300, 301, and 302 and the storage control nodes 400, 401, and 402. The compute nodes 340 and 341 transmit data write requests and data read requests to the storage control nodes 300, 301, and 312 or the storage control nodes 400, 401, and 402 via the storage communication network 311 through user operations and application programs running on the compute nodes. For data to be written, the compute nodes transmit the target data to the storage control node following the write request. For data read, the compute nodes transmit a read request to the storage control node and then receive the target data from the storage control node.
[0036] Each of the HCI nodes 100, 101, 102, the HCI nodes 200, 201, 201, the storage control nodes 300, 301, 302, and the storage control nodes 400, 401, 402 is connected to the key management server 130 via the management communication network 111. The key management server 130 is a server having a function of generating and storing key data required for encryption of data written to a drive (a drive for storing data in the HCI nodes 100, 101, 102 or a drive for storing data in the storage control nodes 300, 301, 302) or a drive box (a drive box 210, 211) and decryption of data read from the drive or the drive box. A major example of a protocol used for communication between the HCI node or the storage control node and the key management server 130 is KMIP (Key Management Interoperability Protocol). Messages transferred according to this protocol are usually protected according to the TLS (Transport Layer Security) protocol.
[0037] Next, the schematic configurations of the HCI node, key management server, drive box, storage control node, compute node, and drive box shown in Figures 1 to 4 will be described with reference to Figures 5, 6, and 7. The functional parts of the HCI node, storage control node, and compute node shown in Figures 1 to 4 will be described with reference to Figures 8, 9, and 10.
[0038] 5 shows an example of the configuration of HCI nodes 100, 101, 102 (with data storage drives), drive boxes 210, 211, storage control nodes 300, 301, 302 (with data storage drives), and key management server 130. These include one or more CPUs 500, one or more memories 505, one or more drives 510 (drive 0) for storing system software programs, application programs, etc., a first network communication unit 507 (Network Interface Card; NIC), a second network communication unit 509 (Host Bus Adapter; HBA), and one or more drives 511, 512, 513 (drives 1, 2, 3) for storing data.
[0039] There may be a plurality of first network communication units 507 and a plurality of second network communication units 509. The first network communication unit 507 and the second network communication unit 509 are interfaces for communicating with other HCI nodes, storage control nodes, compute nodes, and drive boxes via the data communication network 110, the storage communication network 311, and the back-end communication network 310.
[0040] Examples of system software programs stored in the drive 510 include a virtual machine monitor (hypervisor) or a bare metal OS for constructing a virtual environment on the own node, a software program for implementing storage functions (hereinafter referred to as a storage control program), a guest OS that runs on the hypervisor, etc. The storage control program may be in a form that runs on the hypervisor, a guest OS on the hypervisor, or a bare metal OS. In an environment where a hypervisor is operating, the storage control program may run on a guest OS.
[0041] The CPU 500 is a processor that controls the overall operation of the HCI node, the drive box, the storage control node, and the key management server. The memory 505 is implemented using a volatile semiconductor memory such as a static random access memory (SRAM) or a dynamic random access memory (DRAM), or a non-volatile semiconductor memory, and is used as a work memory for the CPU 500 to temporarily store various programs and necessary data. At least one or more CPUs 500 execute the programs stored in the memory 505 to perform various processes described below. The drives 510, 511, 512, and 513 (drives 0, 1, 2, and 3) are configured with large-capacity non-volatile storage devices such as hard disk drives (HDDs), solid state drives (SSDs), and storage class memories (SCMs). These are equipped with interfaces such as non-volatile memory express (NVMe), serial attached SCSI (SAS), and serial ATA (SATA).
[0042] In this embodiment, it is assumed that the encryption-related calculation accelerators 501, 508 (CPUCryptoAcc, NICCryptoAcc) are implemented in both or either of the CPU 500 and the first network communication unit 507. The encryption-related calculation accelerator is hardware dedicated to encryption / decryption, and is a calculation unit incorporated in the CPU 500 or a calculation unit incorporated in the first network communication unit 507. The encryption-related calculation accelerator can be used by passing a dedicated instruction code and a value for the instruction code (e.g., data or an argument, hereinafter referred to as an instruction value) to the CPU 500 and the network communication unit 507. The data for the instruction code is, for example, key data, and the argument for the instruction code is, for example, a variable or key data for referring to the key data passed to the instruction code. It is assumed that the use of the encryption-related calculation accelerator allows the encryption-related processing to be completed faster than the case where the encryption-related calculation accelerator is not used. Details of the programs and data arranged in the memory 505 on the HCI nodes 100, 101, and 102 (each having a data storage drive) will be described later with reference to Fig. 8. Details of the programs and data arranged in the memory 505 on the storage control nodes 300, 301, and 302 (each having a data storage drive) will be described later with reference to Fig. 9.
[0043] Fig. 6 shows an example of the configuration of HCI nodes 200, 201, 202 (without data storage drives) and storage control nodes 400, 401, 402 (without data storage drives). These are the same as the configuration shown in Fig. 5, except that they do not have data storage drives 511, 512, 513. Details of the programs and data arranged in memory 505 of the HCI nodes 200, 201, 202 will be explained later using Fig. 8. Details of the programs and data arranged in memory 505 of the storage control nodes 400, 401, 402 will be explained later using Fig. 9.
[0044] Fig. 7 shows an example of the configuration of the compute nodes 340 and 341. This is the same as the configuration shown in Fig. 5, except that there are no drives 511, 512, and 513 for storing data, and no second network communication unit 509. Details of the programs and data arranged in the memory 505 of the compute nodes 340 and 341 will be described later with reference to Fig. 10.
[0045] Next, the programs and data that are stored in and used in the memory of HCI nodes 100, 101, 102 (with data storage drives), HCI nodes 200, 201, 202 (without data storage drives), storage control nodes 300, 301, 302 (with data storage drives), storage control nodes 400, 401, 402 (without data storage drives), and compute nodes 340, 341 will be explained using Figures 8, 9, and 10.
[0046] 8 shows an example of programs and data stored in the memory 505 of the HCI nodes 100, 101, and 102 (with data storage drive) or the HCI nodes 200, 201, and 202 (without data storage drive). At least the following is stored in the memory 505. Hypervisor 800, command information 801 (information including command code and command value) to be passed to cryptography-related calculation accelerators 501, 508, storage control program 802, HCI node key monitoring program 805, usable key-related information 806 (information regarding keys permitted for use on the HCI node), virtual machine A 810, and virtual machine B 811.
[0047] In addition, in the virtual machine A810, a virtual machine A guest OS812, a plurality of application programs 830 (represented by those with a suffix a), application key information 822 (encryption and decryption key used by application programs running on the virtual machine), a virtual machine A key management program 820 that manages the key, and plaintext data 850 and ciphertext data 851 used by the application programs 830 and the like are arranged. The above is similar to the virtual machine B811, except that ransomware runs. That is, in the virtual machine B811, a virtual machine B guest OS813, a plurality of application programs 831 (represented by those with a suffix d), application key information 823 (encryption and decryption key used by application programs running on the virtual machine), a virtual machine B key management program 821 that manages the key, ransomware 840, and plaintext data 852 and ciphertext data 853 used by the application programs 831, the ransomware 840, and the like are arranged on the memory 505.
[0048] The storage control program 802 controls the writing of data from a virtual machine in the HCI node to a drive or drive box, and the reading of data from a drive or drive box requested by the virtual machine. Some storage control programs 802 encrypt the data before writing it. This encryption function is called stored data encryption. An example of the available key related information 806 in the HCI node is for the above-mentioned stored data encryption. The key related information 806 also includes keys used in multiple virtual machines that have been constructed. The keys used in the virtual machines are placed in memory as part of the available key related information 806 by communication between the HCI node key monitoring program 805 and the virtual machine key management program running on each virtual machine. The roles of the other programs and how data is used will be explained in the explanation of the processing sequence shown in FIG. 15.
[0049] 9 shows an example of programs and data stored in the memory 505 of the storage control nodes 300, 301, and 302 (with data storage drives) or the storage control nodes 400, 401, and 402 (without data storage drives). At least the following are stored in the memory 505. Storage control node OS 900 (bare metal OS for the storage control node), command information 901 (information including command code and command value) to be passed to cryptographic-related calculation accelerators 501, 508, storage control program 902 (StrCtl), storage control node key monitoring program 905, available key related information 906 (information regarding keys permitted for use by the storage control node), ransomware 940, plaintext data 950 and ciphertext data 951 written by the storage control node to a drive or drive box or read from the drive or drive box.
[0050] The function of the storage control program 902 is the same as that of the storage control program 802 in the HCI node, except that the source of the write and read requests to the storage control program is the compute node. Therefore, the key used for encrypting stored data and information related to the key are one example of the available key related information 906, as in the case of the HCI node. In this embodiment, it is assumed that the storage control program 902 runs on the storage control node OS 900, but it may also be that a virtual machine is built on a hypervisor and the storage control program 902 runs on a guest OS in the virtual machine. It is also assumed that the ransomware 940 runs on the storage control node shown in FIG. 9.
[0051] 10 shows an example of programs and data arranged on the memory 705 of the compute nodes 340 and 341. The programs and data arranged on the memory 705 of the compute nodes are the same as those of the HCI nodes, except that there is no storage control program in the memory 705. The numbers given to the arranged programs and data are as follows: A hypervisor 1000, command information 1001 (information including command code and command value) to be passed to the cryptography-related computation accelerators 701, 708, a compute node key monitoring program 1005, available key related information 1006 (information regarding keys permitted for use on the compute node), a virtual machine A 1010, a virtual machine A guest OS 1012, multiple application programs 1030 (the one with the subscript "a" is shown as a representative) running on the virtual machine A guest OS 1012, application key information 1022 (an encryption / decryption key used by an application program running on the virtual machine), and a virtual machine A key manager for managing the keys. The virtual machine B 1011, the virtual machine B guest OS 1013, a plurality of application programs 1031 (the one with the subscript d is shown as a representative) running on the virtual machine B guest OS 1013, application key information 1023 (an encryption / decryption key used by the application programs running on the virtual machine), the virtual machine B key management program 1021 that manages the key, the application program 1031, plaintext data 1052 and ciphertext data 1053 used by the ransomware 1040, etc.
[0052] It is assumed that ransomware 1040 is running on virtual machine B 1011 shown in FIG. 10, similarly to FIG.
[0053] Next, an example of the contents registered in information related to keys that are permitted to be used (usable key related information 806, 906, 1006) that is placed in the memory of the HCI node, storage control node, and compute node will be described with reference to Figures 11, 12, and 13.
[0054] 11 shows an example of usable key related information 806 arranged on the memory of an HCI node. The usable key related information 806 includes at least information for identifying an entity that uses the key (key using entity identifier 1100) and a key value (key value 1101) that is permitted to be used by the entity. In this embodiment, since it is assumed that a storage control program, virtual machine A, and virtual machine B that run on a hypervisor perform encryption and decryption processing, the usable key related information 806 includes registered identifiers for identifying them and key values used by them.
[0055] 11 also includes a hash value 1102 of the key value 1101. This is to enable, for example, when the key length is relatively long, to determine in a shorter time whether the key to be compared is included in the usable key-related information 806 by evaluating whether the hash value of the key to be compared matches the hash value. Therefore, it is not essential that the hash value 1102 is included in the usable key-related information 806. Note that the key value and the hash value are examples of key data.
[0056] 12 shows an example of available key related information 906 stored in the memory of the storage control node. The items included in the available key related information 906 are the same as the items included in the available key related information 806 stored in the memory of the HCI node. In this embodiment, since it is assumed that the entity using the key is only the storage control program, the key using entity identifier 1200 includes only an identifier that identifies the storage control program. When another program performs encryption / decryption processing, the key using entity identifier 1200 that identifies the program and the key value 1201 used by the program are registered in the available key related information 906.
[0057] 13 shows an example of available key related information 1006 arranged in the memory of a compute node. Items included in the available key related information 1006 are the same as the items included in the available key related information 806 arranged in the memory of an HCI node. In this embodiment, since it is assumed that virtual machine A and virtual machine B perform encryption / decryption processing, a key use subject identifier 1300 that identifies them and a key value 1301 used by them are registered in the available key related information 1006. The role and essentiality of the hash value 1302 are also the same as those of the hash value 1102.
[0058] Next, examples of command information 801, 901, and 1001 that are placed on the memory of the HCI node, storage control node, and compute node and passed to the encryption-related calculation accelerator will be described with reference to FIG.
[0059] An instruction code defined for using the encryption-related calculation accelerator is placed in the instruction code 1400. Data or arguments (instruction values) to be passed to the accelerator together with the instruction code 1400 are placed in the data / argument 1401. Fig. 14 shows how a key value is already set in the rdx register, and after this is moved to the xmm1 register, the encryption-related calculation accelerator is caused to generate a key for encryption / decryption using the value set in the xmm1 register and the value "0".
[0060] Next, in the HCI type information processing system shown in Figures 1 and 2, when ransomware encrypts data using a cryptography-related calculation accelerator on virtual machine B running on the information processing system, a processing sequence for preventing the ransomware from infringing data stored on a drive or drive box by overwriting it with ciphertext data will be described with reference to Figure 15.
[0061] The processing sequence shown in FIG. 15 is made up of programs and data arranged on the memory 505 of the HCI node shown in FIG. 8, and communications and processing carried out between the programs and the key management server 130.
[0062] When the HCI nodes 100, 101, 102, 200, 201, 202 (all of the above, numbers omitted below) are started, the storage control program 802 (indicated as H StrCtl in FIG. 15) requests the key data to be used by itself from the key management server 130 (S1500), and the key management server 130 transmits the requested key data to the storage control program 802 (S1501). The request and transmission of the key data do not necessarily have to be performed between the key management server 130. For example, if the information processing system is configured such that the storage control programs 802 operating in each of a plurality of HCI nodes form a cluster and the master node that manages the cluster obtains the key from the key management server 130, the storage control program 802 in each HCI node may issue the request to the storage control program 802 in the master node that obtained the key from the key management server 130, and the master node transmits the requested key data.
[0063] The storage control program 802 stores the received key data in an area of the memory 505 that it manages (S1502).
[0064] Next, the HCI node key monitoring program 805 requests the storage control program 802 for key data to be used by the storage control program 802 (S1510, S1511). Upon receiving the request, the storage control program 802 transmits the key data to be used by itself (S1512, S1513). Upon receiving the key data transmitted by the storage control program 802, the HCI node key monitoring program 805 adds the key data to the available key related information 806 (S1515).
[0065] When the guest OS of the virtual machine built on the hypervisor 800 is started, the virtual machine key management program that manages the key used by the application program running on the virtual machine is also started. FIG. 15 shows the state where the virtual machine B 811 is started (S1520). When the virtual machine B guest OS 813 and the virtual machine B key management program 821 are started, the virtual machine B key management program 821 transmits the key data used by the application program 831 running on the virtual machine B 811 to the HCI node key monitoring program 805 (S1525, S1526, S1527). When the HCI node key monitoring program 805 receives the key data transmitted by the key management program on each virtual machine, it adds the key data to the available key related information 806 (S1528). FIG. 15 shows the state where the request is transmitted to the virtual machine B 811 (S1525 to S1528) as an example, but when multiple virtual machines are built, the same process as above is executed for them. Taking FIG. 8 as an example, a similar process is executed for virtual machine A 810.
[0066] In addition to the processes executed when each virtual machine is started up, if the key data used by each virtual machine is changed (added, updated, deleted, etc.), the key management program on each virtual machine also sends the executed process (added, updated, deleted, etc.) and the new key data (in the case of addition or update) to the HCI node key monitoring program 805.
[0067] Next, a case where ransomware is started in a virtual machine after the virtual machine is started will be described using virtual machine B811 as an example. When the ransomware 840 completes its start (S1530), it reads data stored in a storage area accessible from virtual machine B811. In FIG. 15, the ransomware 840 transmits a data read request to a drive or drive box (S1531, S1532, S1533), and the drive or drive box that receives the request returns the data (S1535, S1536, S1537, S1538). The data received by virtual machine B811 is placed on memory 505 as is (plaintext data 852).
[0068] Next, the ransomware 840 transmits a request to the encryption related computation accelerator 501 to set key data required for encryption together with the key data to be set, to the encryption related computation accelerator 501 in order to encrypt the read plaintext data 852 using the encryption related computation accelerator 501, 508 (hereinafter, assumed to be the encryption related computation accelerator 501) (S1540, S1541, S1542). The data (instruction information 801) passed to the encryption related computation accelerator 501 for setting the key data is the instruction code and instruction value shown in FIG. 14. The above instruction code and instruction value are assumed to take a number of forms, such as a case where a dedicated software program (library, etc.) for using the encryption related computation accelerator 501 that runs on a virtual machine is configured, a case where the ransomware 840 configures them by itself, and the like. Whatever means is used, the hypervisor 800 places them on the memory 505 in order to pass them to the encryption related computation accelerator 501 (S1542). The command information 801 has a format as shown in FIG.
[0069] The HCI node key monitoring program 805 monitors the pair of instruction code and instruction value allocated from the hypervisor 800 to the memory 505. More specifically, the HCI node key monitoring program 805 acquires the instruction code and instruction value allocated to the memory 505 during the process (S1550). When the HCI node key monitoring program 805 acquires the instruction code and instruction value, it checks whether the acquired instruction code is for setting key data in the encryption related calculation accelerator 501. If the HCI node key monitoring program 805 determines that the instruction code is for setting key data in the encryption related calculation accelerator 501 as a result of the check, it checks whether the key data of the instruction value (value specified by data or argument) is a value included in the available key related information 806 that is permitted to be used in the HCI node (S1551). If the HCI node key monitoring program 805 determines that the key data of the instruction value is included in the available key related information 806 as a result of the check, it ends the evaluation. On the other hand, if the HCI node key monitoring program 805 determines that the key data of the command value is not included in the available key related information 806, it requests the storage control program 802 to interrupt processing related to the write request from virtual machine B 811 (S1554, S1555).
[0070] While the HCI node key monitoring program 805 is executing the processes from S1550 to S1555, the ransomware 84 transmits a request to encrypt the plaintext data 852 and the plaintext data 852 to be encrypted to the encryption related calculation accelerator 501 (S1560, S1561, S1562, S1563). When the encryption related calculation accelerator 501 receives the plaintext data 852 in S1563, it encrypts the received plaintext data 852 (S1564). The generated ciphertext data is taken out of the register using an instruction code for the encryption related calculation accelerator 501, transmitted to the virtual machine B 811 (S1565, S1566, S1567), and finally arranged on the memory 505 (ciphertext data 853). Next, the ransomware 840 transmits the ciphertext data 853 and a request to write the ciphertext data 853 (S1570, S1571, S1572).
[0071] The write request for the ciphertext data 853 and the ciphertext data 853 sent by the ransomware 840 are received by the storage control program 802 via the virtual machine B guest OS 813 (S1572). At this time, the storage control program 802 suspends execution of the process related to the write request from the virtual machine B guest OS 813 based on a previously received request to suspend the write process (S1555) (S1573).
[0072] Next, in the 3-tier information processing system shown in Figures 3 and 4, a processing sequence for preventing the ransomware from infringing data stored in a drive or drive box by overwriting it with ciphertext data when the ransomware encrypts data using a cryptography-related calculation accelerator in the storage control node will be described with reference to Figure 16.
[0073] The processing sequence shown in FIG. 16 is made up of programs and data arranged on the memory 505 of the storage control node shown in FIG. 9, and communications and processing carried out between the programs and the key management server 130.
[0074] When the storage control nodes 300, 301, 302, 400, 401, 402 (all of the above, numbers omitted below) are started, the storage control nodes execute processes from S1600 to S1615. These processes are the same as the processes from 1500 to 1515 in Fig. 15, except that the hypervisor 800 is replaced by an OS that runs on the storage control node, and the environment in which each program runs is the storage control node. In Fig. 16, the storage control program 902 is represented as StrCtl.
[0075] Next, a case where the ransomware 940 is started in the storage control node after the storage control node is started will be described. When the ransomware 940 completes its start (S1630), it reads out data stored in a storage area accessible from the storage control program 902. In FIG. 16, the ransomware 940 transmits a data read request to a drive or drive box (S1631, S1632), and the drive or drive box that receives the request returns the data (S1635, S1636, S1637). The returned data is placed in the memory 505 in the same form (plaintext data 950).
[0076] Next, the ransomware 940 transmits a request to the encryption related computation accelerator 501 to set key data required for encryption together with the key data to be set, to the encryption related computation accelerator 501 in order to encrypt the read plaintext data 950 using the encryption related computation accelerator 501, 508 (hereinafter, assumed to be the encryption related computation accelerator 501) (S1640, S1641). The data (command information 901) passed to the encryption related computation accelerator 501 for setting the key data is the command code and command value shown in FIG. 14. The command code and command value are assumed to take a number of forms, such as a case where a dedicated software program (library, etc.) for using the encryption related computation accelerator 501 that runs on a virtual machine is configured, or a case where the ransomware 940 configures them by itself. Whatever means is used, the storage control node OS 900 places them on the memory 505 in order to pass them to the encryption related computation accelerator 501 (S1641). The command information 901 has a format as shown in FIG.
[0077] The storage control node key monitoring program 905 monitors the pair of the instruction code and the instruction value allocated from the storage control node OS 900 to the memory 505. More specifically, the storage control node key monitoring program 905 acquires the instruction code and the instruction value allocated to the memory 505 during the process (S1650). When the storage control node key monitoring program 905 acquires the instruction code and the instruction value, it checks whether the acquired instruction code is for setting key data in the encryption related calculation accelerator 501. When the storage control node key monitoring program 905 determines that the instruction code is for setting key data in the encryption related calculation accelerator 501 as a result of the check, it checks whether the key data of the instruction value (value specified by data or argument) is a value included in the available key related information 906 that is permitted to be used in the storage control node (S1651). When the storage control node key monitoring program 905 determines that the key data of the instruction value is included in the available key related information 906 as a result of the check, it ends the evaluation. On the other hand, if the storage control node key monitoring program 905 determines that the key data of the command value is not included in the available key related information 906, it requests the storage control program 902 to interrupt the write process from the program that sent the command code and command value (S1654, S1655).
[0078] While the storage control node key monitoring program 905 is executing the processes from S1650 to S1655, the ransomware 940 transmits to the encryption related operation accelerator 501 a request to encrypt the plaintext data 950 and the plaintext data 950 to be encrypted (S1660, S1661, S1662). When the encryption related operation accelerator 501 receives the plaintext data 950, it encrypts the received plaintext data 950 (S1664). The generated ciphertext data is taken out of the register using an instruction code for the encryption related operation accelerator 501, transmitted to the storage control program 902 (S1665, S1666), and finally arranged on the memory 505 (ciphertext data 951). Next, the ransomware 940 transmits the ciphertext data 951 and a request to write the ciphertext data 951 (S1670, S1671).
[0079] The storage control program 902 receives the write request for the ciphertext data 951 and the ciphertext data 951 sent by the ransomware 940. At this time, the storage control program 902 suspends execution of the process related to the write request (S1673) based on a request to suspend the write process received in the past (S1655).
[0080] Next, in the 3-tier information processing system shown in Figures 3 and 4, a processing sequence is described with reference to Figure 17 that prevents ransomware from infringing data stored on a drive or drive box by overwriting it with ciphertext data when the ransomware encrypts data using a cryptography-related calculation accelerator in a virtual machine running on a compute node.
[0081] The processing sequence shown in FIG. 17 is made up of communication and processing carried out between the programs and data placed on the memory 705 of the compute node shown in FIG.
[0082] When the guest OS of a virtual machine constructed on the hypervisor 1000 is started, a virtual machine key management program that manages a key used by an application program running on the virtual machine is also started. FIG. 17 shows a state where the virtual machine B 1011 is started (S1720). When the virtual machine B guest OS 1013 and the virtual machine B key management program 1021 are started, the virtual machine B key management program 1021 transmits key data used by the application program 1031 running on the virtual machine B 1011 to the compute node key monitoring program 1005 (S1725, S1726, S1727). When the compute node key monitoring program 1005 receives the key data transmitted by the key management program on each virtual machine, it adds the key data to the available key related information 1006 (S1728). 17 shows, as an example, how the request is sent to virtual machine B 1011 (S1725 to S1728), but if multiple virtual machines are configured, the same processing as above is executed for those virtual machines. Taking FIG. 10 as an example, the same processing is executed for virtual machine A 1010.
[0083] In addition to the processes performed when each virtual machine is started up, if the key data used by each virtual machine is changed (added, updated, deleted, etc.), the key management program on each virtual machine sends the executed process (added, updated, deleted, etc.) and the new key data (in the case of addition or update) to the compute node key monitoring program 1005.
[0084] Next, a case where ransomware is started in a virtual machine after the virtual machine is started will be described using virtual machine B1011 as an example. When the ransomware 1040 completes its start (S1730), it reads data stored in a storage area accessible from virtual machine B1011. In FIG. 17, the ransomware 1040 transmits a data read request to a drive or drive box (S1731, S1732), and the drive or drive box that receives the request returns the data (S1736, S1737, S1738). The data received by virtual machine B1011 is placed directly on memory 705 (plaintext data 1052).
[0085] Next, the ransomware 1040 transmits a request to the encryption related calculation accelerator 701 to set key data required for encryption together with the key data to be set to the encryption related calculation accelerator 701 in order to encrypt the read plaintext data 1052 using the encryption related calculation accelerator 701, 708 (hereinafter, assumed to be the encryption related calculation accelerator 701) (S1740, S1741, S1742). The data (instruction information 1001) passed to the encryption related calculation accelerator 701 for setting the key data is the instruction code and instruction value shown in FIG. 14. The above instruction code and instruction value are assumed to take a number of forms, such as when they are configured by a dedicated software program (library, etc.) for using the encryption related calculation accelerator 701 that runs on a virtual machine, or when they are configured by the ransomware itself. Whatever means is used, the command information 1001 that the hypervisor 1000 places in the memory 705 for delivery to the cryptography related computation accelerator 701 will have the form shown in FIG.
[0086] The compute node key monitoring program 1005 monitors the pair of the instruction code and the instruction value allocated from the hypervisor 1000 to the memory 705. More specifically, the compute node key monitoring program 1005 acquires the instruction code and the instruction value allocated to the memory 705 during the process (S1750). When the compute node key monitoring program 1005 acquires the instruction code and the instruction value, the compute node key monitoring program 1005 checks whether the acquired instruction code is for setting key data in the encryption related computation accelerator 701. If the compute node key monitoring program 1005 determines that the instruction code is for setting key data in the encryption related computation accelerator 701 as a result of the check, the compute node key monitoring program 1005 checks whether the key data of the instruction value (a value specified by data or an argument) is a value included in the available key related information 1006 that is permitted to be used in the compute node (S1751). If the compute node key monitoring program 1005 determines that the key data of the instruction value is included in the available key related information 1006 as a result of the check, the evaluation is terminated. On the other hand, if the compute node key monitoring program 1005 determines that the key data of the command value is not included in the available key related information 1006, it requests the hypervisor 1000 to interrupt processing related to the write request from virtual machine B 1011 (S1754).
[0087] While the compute node key monitoring program 1005 is executing the processes from S1750 to S1754, the ransomware 1040 transmits a request to encrypt the plaintext data 1052 and the plaintext data 1052 to be encrypted to the encryption related calculation accelerator 701 (S1760, S1761, S1762, S1763). When the encryption related calculation accelerator 701 receives the plaintext data 1052 (S1763), it encrypts the received plaintext data 1052 (S1764). The generated ciphertext data is taken out of the register using an instruction code for the encryption related calculation accelerator 701, transmitted to the virtual machine B 1011 (S1765, S1766, S1767), and finally arranged on the memory 705 (ciphertext data 1053). Next, the ransomware 1040 transmits the ciphertext data 1053 and a request to write the ciphertext data 1053 (S1770, S1771, S1772).
[0088] The write request for the ciphertext data 1053 and the ciphertext data 1053 sent by the ransomware 1040 are received by the hypervisor 1000 via the virtual machine B guest OS 1013 (S1772). At this time, the hypervisor 1000 suspends execution of the process related to the write request from the virtual machine B guest OS 1013 based on a previously received request to suspend the write process (S1754) (S1773).
[0089] According to this embodiment, in a node equipped with an accelerator, if ransomware invades a node and uses the accelerator to encrypt data to cause an infringement, the infringement can be prevented at an early stage.
[0090] (II) Supplementary Note The above-described embodiment includes, for example, the following contents.
[0091] In the above embodiment, the present invention is described as being applied to an information processing system, but the present invention is not limited to this and can be widely applied to various other systems, devices, methods, and programs.
[0092] In the above embodiment, the ransomware is permitted to read plaintext data and convert it into ciphertext data using an accelerator, but the ransomware is prohibited from overwriting the data. However, the present invention is not limited to this. For example, when a setting of key data that is not permitted to be used is detected, the reading of data from a drive or drive box, the reading of plaintext data in memory, and the encryption of plaintext data may be prohibited.
[0093] In the above embodiment, the information processing system interrupts the process of writing data to the storage space, but the present invention is not limited to this. For example, the information processing system may interrupt the process of writing data to a storage device (drive or drive box).
[0094] Also, in the above embodiment, the HCI node key monitoring program 805 acquires the command information 801 in S1542, but the present invention is not limited to this. For example, the HCI node key monitoring program 805 may acquire the command information 801 in S1540 or S1541.
[0095] In the above embodiment, the storage control node key monitoring program 905 acquires the command information 901 in S1641, but the present invention is not limited to this. For example, the storage control node key monitoring program 905 may acquire the command information 901 in S1640.
[0096] In the above embodiment, the compute node key monitoring program 1005 acquires the command information 1001 in S1742, but the present invention is not limited to this. For example, the compute node key monitoring program 1005 may acquire the command information 1001 in S1740 or S1741.
[0097] The above-described embodiment has the following characteristic configurations, for example.
[0098] (1) An information processing system (e.g., an HCI type information processing system) includes an accelerator (e.g., encryption-related operation accelerators 501, 508) capable of encrypting data, a storage device (e.g., a drive, a drive box), a compute unit (e.g., a hypervisor 800, a virtual machine A 810, a virtual machine B 811) that operates an application program (e.g., application programs 830, 831), a storage control unit (e.g., a storage control program 802) that processes a request issued by the compute unit to read and write data in a specific storage space according to an instruction issued by the application program, and command information (e.g., and a monitoring unit (e.g., an HCI node key monitoring program 805) that monitors an application program (e.g., command information 801), and if the monitoring unit detects that the key data set in the accelerator by the command information is not key data that is permitted to be used, it issues an interruption request to the storage control unit to interrupt the process related to writing of data (e.g., S1554, S1555), and the compute unit, upon receiving an instruction from the application program, reads data from the storage device (e.g., S1531 to S1538), encrypts the read data using the accelerator (e.g., S1560 to S1567), and issues an instruction to the storage control unit to write the encrypted data to the storage device (e.g., S1570 to S1572), and if the storage control unit has received the interruption request, it interrupts the process related to writing of data to the storage device (e.g., S1573).
[0099] In the above configuration, for example, if it is detected that the key data to be set in the accelerator is unauthorized key data, the write process is not performed, thereby preventing the data in the storage device from being overwritten after the key data is set by ransomware.
[0100] (2) The compute unit includes a plurality of virtual machines capable of running application programs, and the virtual machines of the compute unit issue command information to set, in the accelerator, key data to be used by the virtual machine, which is specified by the application program provided in the virtual machine so that the application program encrypts data using the accelerator (e.g., S1540 to S1542), and when the monitoring unit detects that the key data set by the command information is not key data whose use is permitted, it issues an interrupt request to the storage control unit to interrupt processing relating to writing of data by the virtual machine that issued the command information (e.g., S1554, S1555), and when the storage control unit receives the interrupt request, it interrupts processing relating to writing of data by the virtual machine to the storage device.
[0101] In the above configuration, for example, the HCI node suspends data writing by a virtual machine infected with ransomware, but does not suspend data writing by other virtual machines, thereby localizing the impact on the system.
[0102] (3) An information processing system (e.g., a 3-tier information processing system) includes an accelerator (e.g., encryption-related operation accelerators 501, 508) capable of encrypting data, a storage device (e.g., a drive, a drive box), a storage control unit (e.g., a storage control program 902) that processes data to be read and written to the storage device, a compute unit (e.g., a storage control node OS 900) that operates the storage control unit, and a monitoring unit (e.g., a storage control node key monitoring program 901) that monitors command information (e.g., command information 901) issued from the compute unit that sets, in the accelerator, key data used by the storage control unit, which is specified by the application program, in order for an application program to encrypt data using the accelerator. 905), and when the monitoring unit detects that the key data set in the accelerator by command information is not key data that is permitted to be used, the monitoring unit issues an interruption request to the storage control unit to interrupt processing related to writing of data (e.g., S1654, S1655), and the compute unit, upon receiving an instruction from an application program, reads data from the storage device (e.g., S1631 to S1637), encrypts the read data using the accelerator (e.g., S1660 to S1666), and issues an instruction to the storage control unit to write the encrypted data to the storage device (e.g., S1670 to S1671), and when the storage control unit has received the interruption request, it interrupts processing related to writing of data to the storage device (e.g., S1673).
[0103] According to the above configuration, for example, if ransomware invades a storage control node, it is possible to prevent data in the storage device from being overwritten.
[0104] (4) The information processing system (e.g., a 3-tier information processing system) includes an accelerator (e.g., encryption-related operation accelerators 701, 708) capable of encrypting data, a compute unit (e.g., a hypervisor 1000, a virtual machine A 1010, a virtual machine B 1011) that issues to a storage control node (e.g., storage control nodes 300, 301, 302, 400, 401, 402) a request to read and write data in a specific storage space issued by the compute unit according to an instruction issued by the application program, and a key data used by the compute unit specified by the application program in order for the application program to encrypt data using the accelerator. and a monitoring unit (e.g., a compute node key monitoring program 1005) that monitors command information (command information 1001) issued from the compute unit to be set in the accelerator. If the monitoring unit detects that the key data set in the accelerator by the command information is not key data that is permitted to be used, it issues an interrupt request to the compute unit to interrupt the process related to writing data (e.g., S1754). Upon receiving an instruction from the application program, the compute unit reads data from a storage device (e.g., S1731 to S1738) and encrypts the read data using the accelerator (e.g., S1760 to S1767). If the interrupt request has been received, it interrupts issuance of an instruction to write the encrypted data to the storage device (e.g., S1773).
[0105] According to the above configuration, for example, if ransomware invades a compute node, it is possible to prevent data in a storage device from being overwritten.
[0106] (5) The compute unit includes a plurality of virtual machines capable of running application programs, and the virtual machines of the compute unit issue command information to set, in the accelerator, key data to be used by the virtual machine specified by the application program so that the application program provided in the virtual machine encrypts data using the accelerator (e.g., S1741, S1742). When the monitoring unit detects that the key data set by the command information is not key data that is permitted to be used, the monitoring unit issues an interrupt request to the compute unit to interrupt processing related to writing data by the virtual machine that issued the command information (e.g., S1754). When the compute unit receives the interrupt request, the computing unit interrupts issuance of an instruction for the virtual machine to write data to the storage device (e.g., S1773).
[0107] In the above configuration, for example, a compute node can suspend data writing from a virtual machine infected with ransomware, but not suspend data writing from other virtual machines, thereby localizing the impact on the system.
[0108] Furthermore, the above-described configurations may be modified, rearranged, combined, or omitted as appropriate without departing from the spirit and scope of the present invention.
[0109] It should be understood that items listed in the format "at least one of A, B, and C" can mean (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C). Similarly, items listed in the format "at least one of A, B, or C" can mean (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C). [Explanation of symbols]
[0110] 100...HCI node (with data storage drive), 200...HCI node (without data storage drive), 300...storage control node (with data storage drive), 340...compute node, 400...storage control node (without data storage drive).
Claims
1. An accelerator, which is hardware capable of encrypting data; A storage device; a compute unit including multiple virtual machines each capable of running an application program; a storage control unit that processes a request to read and write data in a specific storage space, the request being issued by the compute unit in accordance with an instruction issued by an application program in any one of the plurality of virtual machines; The monitoring department and Equipped with Each of the plurality of virtual machines of the compute unit issues command information for setting key data to the accelerator, the key data being used by an application program provided in the virtual machine to encrypt data using the accelerator; The monitoring unit is monitoring command information that may be issued from each of the plurality of virtual machines, and acquiring the command information when command information is issued from any of the virtual machines; when it is detected that the key data set in the accelerator based on the acquired command information is not key data that is permitted to be used, an interruption request is issued to the storage control unit to interrupt a process related to writing data by the virtual machine that issued the command information; The compute unit, upon receiving an instruction from an application program, reads data from the storage device, encrypts the read data using the accelerator, and issues a request to the storage control unit to write the encrypted data; when the storage control unit has received the interruption request for a virtual machine having the application program, interrupting a process related to writing data by the virtual machine, the process being related to writing to a storage device or storage space to which data can be read or written by any of the plurality of virtual machines; Information processing system.
2. An accelerator, which is hardware capable of encrypting data; a computing unit including a plurality of virtual machines each capable of running an application program, the computing unit issuing a request to a storage control node to read and write data in a specific storage space in accordance with an instruction issued by an application program in any one of the plurality of virtual machines; The monitoring department and Equipped with Each of the plurality of virtual machines of the compute unit issues command information for setting key data to the accelerator, the key data being used by an application program provided in the virtual machine to encrypt data using the accelerator; The monitoring unit is monitoring command information that may be issued from each of the plurality of virtual machines, and acquiring the command information when command information is issued from any of the virtual machines; when it is detected that the key data set in the accelerator based on the acquired command information is not key data that is permitted to be used, an interrupt request is issued to the compute unit to interrupt a process related to writing data by a virtual machine that issued the command information; The compute unit, upon receiving an instruction from an application program, is configured to read data from a storage device, encrypt the read data using the accelerator, and issue a request to the storage control node to write the encrypted data to the storage device. When the interruption request is received, the compute unit interrupts issuance of a request to write the encrypted data to a storage device or storage space from which data can be read or written by any of the multiple virtual machines. Information processing system.
Citation Information
Patent Citations
Deiizeruhatsudensochiniokeru teienerugiikaishushisutemu
JP1976017748A
Storage system executing encryption processing
JP2005322201A
Malware detection device, malware detection method, and malware detection program
JP2019021131A
System and method for securely storing user information in a user profile
JP2019521537A
Ransomware blocking device and blocking method using content file access control
JP2019531519A